Homework Flashcards
1
Q
Windows Task Manager
A
Shows processes from all users
names, descriptions
2
Q
Process Explorer
A
procexp.exe
- shows processes for all users
- shows parent processes
3
Q
Indicators of malware
A
- wrong parent process
- bad path
- renamed file
- description doesn’t match name
4
Q
malware perisistence
A
whenever system reboot, malware relaunches
“autoruns”
5
Q
autoruns
A
processes and applications launched automatically when a system is rebooted.
6
Q
autoruns.exe
A
- Sysinternals tool which shows autorun locations/values
- registry and non-registry locations
- allows for “Compare to Saved AutoRuns File…”
- changes shown in “green”
7
Q
autoruns.exe categories
A
Logon Explorer Internet Explorer Scheduled Tasks Services Drivers Codecs Boot Execute Image Hijacks AppInit KnownDLLs Winlogon Winsock Providers Print Monitors LSA Providers Network Providers WMI Sidebar Gadgets